F5-K000133233: High severity f5 nginx instance manager vulnerability
NGINX Management Suite default file permissions are set such that an authenticated attacker may be able to modify sensitive files on NGINX Instance Manager and NGINX API Connectivity Manager.
Affected Software
Event History
Frequently Asked Questions
What is the severity of F5-K000133233?
The severity of F5-K000133233 is classified as critical due to the risk of sensitive file modifications by authenticated attackers.
How do I fix F5-K000133233?
To fix F5-K000133233, ensure you update to the remedied versions of NGINX Instance Manager, NGINX API Connectivity Manager, and NGINX Security Monitoring as specified in the advisory.
Which versions are affected by F5-K000133233?
F5-K000133233 affects NGINX Instance Manager versions 1.0.0 to 2.8.0 and NGINX API Connectivity Manager versions 1.0.0 to 1.4.1.
Who is impacted by F5-K000133233?
Users of affected versions of NGINX Instance Manager, NGINX API Connectivity Manager, and NGINX Security Monitoring are impacted by F5-K000133233.
What type of attacks does F5-K000133233 enable?
F5-K000133233 potentially enables authenticated attackers to modify sensitive configuration files on the affected systems.